Survey research reports that 55% of small businesses say a financial loss of $50,000 or less from a successful cyberattack would shut them down, with 32% saying a loss as low as $10,000 would do it.
Put Those Figures Next To The Ones This Corpus Quotes
$3.54 million average retail breach cost, at 25-0808. $6.08 million for financial institutions, at 25-0616. $5.08 million for law firms, at 25-0910. A $75 million ransom payment, at 25-0728. $1.5 million in response costs for a statewide incident, at 25-1127.
Every one of those is one to three orders of magnitude above the threshold that would end a third of small businesses.
This desk has repeatedly said that averages across a distribution containing both a corner shop and a company reporting a nine-figure loss describe nobody. This is the clearest available demonstration: the average is not merely unhelpful to a small firm, it is off the scale of that firm’s survival.
And It Makes The Ransom Demand A Different Object
The extortion economics in this corpus assume a victim weighing payment against recovery cost — the calculation at 25-0921, where Nevada refused because it could restore, and at 25-1231, where the counterparty may not exist next month.
A firm for which a $10,000 loss is terminal has no negotiating position. It cannot afford the incident, the recovery, or the ransom, and the outcome is decided before anyone speaks.
The Obvious Implication Is Uncomfortable
If a third of small businesses cannot absorb $10,000, then almost no security investment is affordable to them either — not incident response retainers, not the pre-negotiated vendor agreements that worked at 25-0921, not meaningful staffing.
The corpus has no answer to this. Graded medium: self-reported survey responses to hypotheticals, and the finding is directionally consistent with everything else in the small-business set.
Built on published survey research, listed below. Figures are self-reported and describe hypothetical scenarios. Corrections: corrections@forensicpost.com.